Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2gqp-7qqf-5rcq

больше 4 лет назад

All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths.

EPSS: Низкий
github логотип

GHSA-2gqm-82cj-qxfq

больше 3 лет назад

A vulnerability has been identified in Solid Edge SE2022 (All versions < V2210Update12), Solid Edge SE2023 (All versions < V2023Update2). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gqj-p7m3-px6g

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the category page in VCD-db 0.98 and earlier allows remote attackers to inject arbitrary web script or HTML via the batch parameter.

EPSS: Низкий
github логотип

GHSA-2gqj-jjm7-f6m7

около 4 лет назад

Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

EPSS: Низкий
github логотип

GHSA-2gqh-hpcc-jmx2

около 4 лет назад

There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2gqh-f9c6-5m85

около 4 лет назад

In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gqh-f22g-jh9g

больше 2 лет назад

A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2gqg-xm37-vrf5

4 дня назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gqg-96r8-5h58

почти 2 года назад

Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gqg-8593-7cc7

больше 4 лет назад

ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.

EPSS: Низкий
github логотип

GHSA-2gqg-2rg7-gh33

около 4 лет назад

Cross site scripting in librenms

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2gqg-2j56-fxgf

около 4 лет назад

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gqf-hxr7-jh68

около 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending crafted requests that contain overly large values to an affected device, causing a stack overflow. A successful exploit could allow the attacker to cause the device to crash or allow the attacker to execute arbitrary code with root privileges on the underlying operating system.

EPSS: Низкий
github логотип

GHSA-2gqc-rq92-c366

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or (2) error parameter to users/index.

EPSS: Низкий
github логотип

GHSA-2gqc-hf8q-hvqq

почти 4 года назад

The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2gqc-83gq-256v

6 месяцев назад

IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to server-side enforcement of client-side security.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2gqc-6j2q-83qp

7 месяцев назад

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

EPSS: Низкий
github логотип

GHSA-2gq9-rqpm-h5mw

около 4 лет назад

There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2gq9-pvgx-5r3p

5 месяцев назад

Rejected reason: The reporter agreed to not assign CVE ID

EPSS: Низкий
github логотип

GHSA-2gq9-2c38-4pvg

9 месяцев назад

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. On Cloud instances, this issue allows for metadata retrieving.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gqp-7qqf-5rcq

All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2gqm-82cj-qxfq

A vulnerability has been identified in Solid Edge SE2022 (All versions < V2210Update12), Solid Edge SE2023 (All versions < V2023Update2). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gqj-p7m3-px6g

Cross-site scripting (XSS) vulnerability in the category page in VCD-db 0.98 and earlier allows remote attackers to inject arbitrary web script or HTML via the batch parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2gqj-jjm7-f6m7

Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

9%
Низкий
около 4 лет назад
github логотип
GHSA-2gqh-hpcc-jmx2

There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gqh-f9c6-5m85

In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gqh-f22g-jh9g

A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

CVSS3: 8.8
60%
Средний
больше 2 лет назад
github логотип
GHSA-2gqg-xm37-vrf5

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.

CVSS3: 7.8
0%
Низкий
4 дня назад
github логотип
GHSA-2gqg-96r8-5h58

Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2gqg-8593-7cc7

ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2gqg-2rg7-gh33

Cross site scripting in librenms

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gqg-2j56-fxgf

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2gqf-hxr7-jh68

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are sufficient to log in to the web-based management interface could exploit each vulnerability by sending crafted requests that contain overly large values to an affected device, causing a stack overflow. A successful exploit could allow the attacker to cause the device to crash or allow the attacker to execute arbitrary code with root privileges on the underlying operating system.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2gqc-rq92-c366

Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or (2) error parameter to users/index.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2gqc-hf8q-hvqq

The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.

CVSS3: 9.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-2gqc-83gq-256v

IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to server-side enforcement of client-side security.

CVSS3: 3.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-2gqc-6j2q-83qp

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

0%
Низкий
7 месяцев назад
github логотип
GHSA-2gq9-rqpm-h5mw

There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gq9-pvgx-5r3p

Rejected reason: The reporter agreed to not assign CVE ID

5 месяцев назад
github логотип
GHSA-2gq9-2c38-4pvg

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. On Cloud instances, this issue allows for metadata retrieving.

CVSS3: 6.8
0%
Низкий
9 месяцев назад

Уязвимостей на страницу